Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.20%—Dashboard TO DO ListAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.3.1.
AplazadaMedia (4.4)0.36%—Announce From THE DashboardAI4/4/202417/6/2026
The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
AnalizadaAlta (7.5)0.80%—Cisco Nexus Dashboard Fabric Controller3/4/202417/6/2026
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through…
AnalizadaMedia (4.3)0.38%—Cisco Nexus Dashboard Orchestrator3/4/202417/6/2026
A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user…
AnalizadaMedia (4.3)0.41%—Cisco Nexus Dashboard3/4/202417/6/2026
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A…
AnalizadaMedia (6)0.17%—Cisco Nexus Dashboard3/4/202417/6/2026
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this…
AnalizadaAlta (8.8)0.26%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator3/4/202417/6/2026
A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the…
AplazadaMedia (6.5)0.36%—Buffercode Frontend DashboardAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06. Frontend Dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through 2.2.1.
AplazadaMedia (5.4)0.46%—Sharethis Dashboard FOR Google AnalyticsAI25/3/202417/6/2026
Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4.
AnalizadaMedia (5.4)0.81%💥 ExploitBowo System Dashboard20/3/202417/6/2026
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks
ModificadaAlta (8.8)0.22%—Automattic Crowdsignal Dashboard16/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
ModificadaMedia (4.3)0.30%—Mainwp Dashboard13/3/202417/6/2026
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated…
AnalizadaMedia (4.3)0.40%—Jeroensormani WP Dashboard Notes27/2/202417/6/2026
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and…
AnalizadaAlta (8.4)0.23%—TD Advanced Dashboard21/2/202417/6/2026
The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.
ModificadaMedia (6.1)0.35%—Automattic Crowdsignal Dashboard10/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
ModificadaCrítica (9.8)2.0%💥 PoCStimulsoft Dashboards.php6/2/20249/7/2026
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
ModificadaMedia (6.1)0.83%💥 PoCStimulsoft Dashboard.js5/2/20249/7/2026
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
ModificadaMedia (5.4)0.76%💥 PoCStimulsoft Dashboards.js5/2/20249/7/2026
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.
ModificadaAlta (8.8)0.19%—Custom Dashboard Widgets Project Custom Dashboard Widgets31/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1.
ModificadaAlta (8.2)0.46%—Flatlogic React Dashboard30/1/202417/6/2026
react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.
ModificadaMedia (4.8)0.40%—Davidvongries Ultimate Dashboard21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11.
ModificadaMedia (4.9)0.55%—Mainwp Dashboard20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.
ModificadaMedia (4.8)0.39%—Plugin-planet Dashboard Widget Suite14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1.
ModificadaMedia (6.1)0.40%—Deconf Clicky Analytics Dashboard14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
ModificadaCrítica (9.8)0.71%—Joomcode Jcdashboard14/12/202317/6/2026
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
Orbitaley — Vulnerabilidades